CVE-2019-17621

CRITICALCVSS 9.8/10Actively ExploitedEPSS 89.62%

Last modified

CVE-2019-17621 is a critical-severity vulnerability rated 9.8/10 on the CVSS scale. The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.. CISA has confirmed active exploitation in the wild. EPSS estimates a 89.62% chance of exploitation in the next 30 days.

Description

The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.

Metrics

CVSS 3.1
9.8/10

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

EPSS Probability
89.62%

99.8th percentile

Probability of exploitation in the next 30 days. Learn more

Exploitation Status

This vulnerability is listed in CISA’s Known Exploited Vulnerabilities catalog, confirming active exploitation in the wild. Federal agencies must remediate by .

Weakness Enumeration

Affected Software

VendorProductVersionsUpdate
DlinkDir-859 Firmware<= 1.05b03
DlinkDir-859 Firmware1.06b01Beta1
DlinkDir-822 Firmware<= 2.03b01
DlinkDir-822 Firmware<= 3.12b04
DlinkDir-823 Firmware<= 1.00b06
DlinkDir-823 Firmware1.00b06Beta
DlinkDir-865l Firmware<= 1.07b01
DlinkDir-868l Firmware<= 1.12b04
DlinkDir-868l Firmware<= 2.05b02
DlinkDir-869 Firmware<= 1.03b02
DlinkDir-869 Firmware1.03b02Beta02
DlinkDir-880l Firmware<= 1.08b04
DlinkDir-890l Firmware<= 1.11b01
DlinkDir-890l Firmware1.11b01Beta01
DlinkDir-890r Firmware<= 1.11b01
DlinkDir-890r Firmware1.11b01Beta01
DlinkDir-885l Firmware<= 1.12b05
DlinkDir-885r Firmware<= 1.12b05
DlinkDir-895l Firmware<= 1.12b10
DlinkDir-895r Firmware<= 1.12b10
DlinkDir-818lx FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Analyzed

Frequently Asked Questions

What is CVE-2019-17621?
The UPnP endpoint URL /gena.cgi in the D-Link DIR-859 Wi-Fi router 1.05 and 1.06B01 Beta01 allows an Unauthenticated remote attacker to execute system commands as root, by sending a specially crafted HTTP SUBSCRIBE request to the UPnP service when connecting to the local network.
How severe is CVE-2019-17621?
CVE-2019-17621 has a CVSS score of 9.8/10 (CRITICAL severity). The EPSS model estimates a 89.62% probability of exploitation in the next 30 days. This vulnerability is listed in CISA's Known Exploited Vulnerabilities catalog.
How do I fix CVE-2019-17621?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2019-17621?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST